用多模态AI检测电力系统异常,提升安全防护能力。
Large Language Models for Power System Security: A Novel Multi-Modal Approach for Anomaly Detection in Energy Management Systems
- 结合视觉标记与语言规则,实现对人机界面的多模态异常检测。
- 在IEEE 14节点系统上验证有效,可识别数值方法遗漏的视觉异常。
- 针对电力管理系统全流程漏洞设计,适合电网安全研究人员参考。
本文提出一种面向能源管理系统(EMS)的安全框架,系统性识别数据处理全流程中的漏洞,包括状态估计后隐蔽攻击、数据库篡改及基于实时数据库(RTDB)存储的人机界面(HMI)显示污染。针对现代攻击向量的复杂性,首次在电力系统领域引入生成式AI(GenAI)驱动的异常检测系统(ADS)。进一步提出一套集合标记生成智能(SoM-GI)框架,通过融合视觉标志与语言规则,克服生成模型在空间推理上的局限。该方法利用系统化视觉指标,精准解析分段HMI画面,检测数值方法无法捕捉的视觉异常。在IEEE 14-Bus系统上的验证表明,该框架在多种场景下均具有效性,视觉分析成功识别出不一致之处。整合数值分析、视觉模式识别与语言规则,形成对网络威胁与系统错误的综合防御机制。
原文摘要 · Abstract (English)
This paper elaborates on an extensive security framework specifically designed for energy management systems (EMSs), which effectively tackles the dynamic environment of cybersecurity vulnerabilities and/or system problems (SPs), accomplished through the incorporation of novel methodologies. A comprehensive multi-point attack/error model is initially proposed to systematically identify vulnerabilities throughout the entire EMS data processing pipeline, including post state estimation (SE) stealth attacks, EMS database manipulation, and human-machine interface (HMI) display corruption according to the real-time database (RTDB) storage. This framework acknowledges the interconnected nature of modern attack vectors, which utilize various phases of supervisory control and data acquisition (SCADA) data flow. Then, generative AI (GenAI)-based anomaly detection systems (ADSs) for EMSs are proposed for the first time in the power system domain to handle the scenarios. Further, a set-of-mark generative intelligence (SoM-GI) framework, which leverages multimodal analysis by integrating visual markers with rules considering the GenAI capabilities, is suggested to overcome inherent spatial reasoning limitations. The SoM-GI methodology employs systematic visual indicators to enable accurate interpretation of segmented HMI displays and detect visual anomalies that numerical methods fail to identify. Validation on the IEEE 14-Bus system shows the framework's effectiveness across scenarios, while visual analysis identifies inconsistencies. This integrated approach combines numerical analysis with visual pattern recognition and linguistic rules to protect against cyber threats and system errors.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。